<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>krscreenconnect.com - osintafrica</title>
	<atom:link href="https://www.osintafrica.net/tag/krscreenconnect-com/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.osintafrica.net</link>
	<description>intelligency blog</description>
	<lastBuildDate>Wed, 19 Mar 2025 19:07:31 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>

<image>
	<url>https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/05/cropped-osintafrica-1.jpg?fit=32%2C32&#038;ssl=1</url>
	<title>krscreenconnect.com - osintafrica</title>
	<link>https://www.osintafrica.net</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">221010672</site>	<item>
		<title>Malicious ConnectWise Control application downloaded in the wild</title>
		<link>https://www.osintafrica.net/malicious-connectwise-control-application-downloaded-in-the-wild/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=malicious-connectwise-control-application-downloaded-in-the-wild</link>
		
		<dc:creator><![CDATA[Bangaly Koita]]></dc:creator>
		<pubDate>Wed, 19 Mar 2025 19:07:31 +0000</pubDate>
				<category><![CDATA[Main News]]></category>
		<category><![CDATA[192.159.99.10]]></category>
		<category><![CDATA[7631a79a9071099fa4803e1c4c5df207]]></category>
		<category><![CDATA[ClickOnceRunner.pdb]]></category>
		<category><![CDATA[ConnectWise Control 23.2.9.8466]]></category>
		<category><![CDATA[krscreenconnect.com]]></category>
		<category><![CDATA[support.client.exe]]></category>
		<guid isPermaLink="false">https://www.osintafrica.net/?p=877</guid>

					<description><![CDATA[<p>ConnectWise ScreenConnect is a self-hosted remote desktop software application. The tool is used by thousand...</p>
<p>The post <a href="https://www.osintafrica.net/malicious-connectwise-control-application-downloaded-in-the-wild/">Malicious ConnectWise Control application downloaded in the wild</a> first appeared on <a href="https://www.osintafrica.net">osintafrica</a>.</p>]]></description>
										<content:encoded><![CDATA[<p id="50cb" class="pw-post-body-paragraph lx ly go lz b ma mb mc md me mf mg mh mi mj mk ml mm mn mo mp mq mr ms mt mu gh bk" data-selectable-paragraph="">ConnectWise ScreenConnect is a self-hosted remote desktop software application. The tool is used by thousand of people, Companies, businesses around the world.</p>
<p id="e41b" class="pw-post-body-paragraph lx ly go lz b ma mb mc md me mf mg mh mi mj mk ml mm mn mo mp mq mr ms mt mu gh bk" data-selectable-paragraph="">As a well-known tool, abusing it, could help the threat actor to compromised many systems and organization by gaining unauthorized access to the computer or environment.</p>
<p id="e5ec" class="pw-post-body-paragraph lx ly go lz b ma mb mc md me mf mg mh mi mj mk ml mm mn mo mp mq mr ms mt mu gh bk" data-selectable-paragraph="">The malicious application is called ConnectWise Control 23.2.9.8466. Quite similar to the naming convention used by ConnectWise ScreenConnect application.</p>
<p id="413a" class="pw-post-body-paragraph lx ly go lz b ma mb mc md me mf mg mh mi mj mk ml mm mn mo mp mq mr ms mt mu gh bk" data-selectable-paragraph="">The malicious tool is available from the website krscreenconnect[.]com.</p>
<p id="f25a" class="pw-post-body-paragraph lx ly go lz b ma mb mc md me mf mg mh mi mj mk ml mm mn mo mp mq mr ms mt mu gh bk" data-selectable-paragraph="">At the time of writing, the tool been downloaded by many users and organizations.</p>
<p id="8b05" class="pw-post-body-paragraph lx ly go lz b ma mb mc md me mf mg mh mi mj mk ml mm mn mo mp mq mr ms mt mu gh bk" data-selectable-paragraph="">The domain name is quite new:</p>
<p id="7795" class="pw-post-body-paragraph lx ly go lz b ma mb mc md me mf mg mh mi mj mk ml mm mn mo mp mq mr ms mt mu gh bk" data-selectable-paragraph="">The domain is newly created:</p>
<p id="458c" class="pw-post-body-paragraph lx ly go lz b ma mb mc md me mf mg mh mi mj mk ml mm mn mo mp mq mr ms mt mu gh bk" data-selectable-paragraph="">Dates 50 days old</p>
<p id="98bb" class="pw-post-body-paragraph lx ly go lz b ma mb mc md me mf mg mh mi mj mk ml mm mn mo mp mq mr ms mt mu gh bk" data-selectable-paragraph="">Created on 2025–01–26</p>
<p id="cae3" class="pw-post-body-paragraph lx ly go lz b ma mb mc md me mf mg mh mi mj mk ml mm mn mo mp mq mr ms mt mu gh bk" data-selectable-paragraph="">Expires on 2026–01–26</p>
<p id="8bdb" class="pw-post-body-paragraph lx ly go lz b ma mb mc md me mf mg mh mi mj mk ml mm mn mo mp mq mr ms mt mu gh bk" data-selectable-paragraph="">Updated on 2025–01–26</p>
<p id="4670" class="pw-post-body-paragraph lx ly go lz b ma mb mc md me mf mg mh mi mj mk ml mm mn mo mp mq mr ms mt mu gh bk" data-selectable-paragraph="">Hosted on dedicated server with the IP address 192.159.99.10.</p>
<p id="78d3" class="pw-post-body-paragraph lx ly go lz b ma mb mc md me mf mg mh mi mj mk ml mm mn mo mp mq mr ms mt mu gh bk" data-selectable-paragraph="">The application is available to download after connecting to the website via the link: hxxps://krscreenconnect[.]com/bin/support.client.exe?i&amp;e=Support&amp;y=Guest&amp;r.</p>
<p id="0b9e" class="pw-post-body-paragraph lx ly go lz b ma mb mc md me mf mg mh mi mj mk ml mm mn mo mp mq mr ms mt mu gh bk" data-selectable-paragraph="">To fully investigate the application, we used couple of tools such as app any run, Virus total, urlscan, Domaintools, Censys.</p>
<p id="2711" class="pw-post-body-paragraph lx ly go lz b ma mb mc md me mf mg mh mi mj mk ml mm mn mo mp mq mr ms mt mu gh bk" data-selectable-paragraph="">First of all, we wanted to have the hash of the executable file “support.client.exe” or see what is behind the URL. To achieve that, we used: <a class="ag mv" href="https://urlscan.io/search/#krscreenconnect.com" target="_blank" rel="noopener ugc nofollow">Search — urlscan.io</a></p>
<p id="eb8d" class="pw-post-body-paragraph lx ly go lz b ma mb mc md me mf mg mh mi mj mk ml mm mn mo mp mq mr ms mt mu gh bk" data-selectable-paragraph="">we got the following details:</p>
<figure class="mz na nb nc nd ne mw mx paragraph-image">
<div class="nf ng fd nh bh ni" tabindex="0" role="button">
<div class="mw mx my"><picture><source srcset="https://miro.medium.com/v2/resize:fit:640/format:webp/1*JkBf-4djpgm6yQZo37hAvg.png 640w, https://miro.medium.com/v2/resize:fit:720/format:webp/1*JkBf-4djpgm6yQZo37hAvg.png 720w, https://miro.medium.com/v2/resize:fit:750/format:webp/1*JkBf-4djpgm6yQZo37hAvg.png 750w, https://miro.medium.com/v2/resize:fit:786/format:webp/1*JkBf-4djpgm6yQZo37hAvg.png 786w, https://miro.medium.com/v2/resize:fit:828/format:webp/1*JkBf-4djpgm6yQZo37hAvg.png 828w, https://miro.medium.com/v2/resize:fit:1100/format:webp/1*JkBf-4djpgm6yQZo37hAvg.png 1100w, https://miro.medium.com/v2/resize:fit:1400/format:webp/1*JkBf-4djpgm6yQZo37hAvg.png 1400w" type="image/webp" sizes="(min-resolution: 4dppx) and (max-width: 700px) 50vw, (-webkit-min-device-pixel-ratio: 4) and (max-width: 700px) 50vw, (min-resolution: 3dppx) and (max-width: 700px) 67vw, (-webkit-min-device-pixel-ratio: 3) and (max-width: 700px) 65vw, (min-resolution: 2.5dppx) and (max-width: 700px) 80vw, (-webkit-min-device-pixel-ratio: 2.5) and (max-width: 700px) 80vw, (min-resolution: 2dppx) and (max-width: 700px) 100vw, (-webkit-min-device-pixel-ratio: 2) and (max-width: 700px) 100vw, 700px" /><source srcset="https://miro.medium.com/v2/resize:fit:640/1*JkBf-4djpgm6yQZo37hAvg.png 640w, https://miro.medium.com/v2/resize:fit:720/1*JkBf-4djpgm6yQZo37hAvg.png 720w, https://miro.medium.com/v2/resize:fit:750/1*JkBf-4djpgm6yQZo37hAvg.png 750w, https://miro.medium.com/v2/resize:fit:786/1*JkBf-4djpgm6yQZo37hAvg.png 786w, https://miro.medium.com/v2/resize:fit:828/1*JkBf-4djpgm6yQZo37hAvg.png 828w, https://miro.medium.com/v2/resize:fit:1100/1*JkBf-4djpgm6yQZo37hAvg.png 1100w, https://miro.medium.com/v2/resize:fit:1400/1*JkBf-4djpgm6yQZo37hAvg.png 1400w" sizes="(min-resolution: 4dppx) and (max-width: 700px) 50vw, (-webkit-min-device-pixel-ratio: 4) and (max-width: 700px) 50vw, (min-resolution: 3dppx) and (max-width: 700px) 67vw, (-webkit-min-device-pixel-ratio: 3) and (max-width: 700px) 65vw, (min-resolution: 2.5dppx) and (max-width: 700px) 80vw, (-webkit-min-device-pixel-ratio: 2.5) and (max-width: 700px) 80vw, (min-resolution: 2dppx) and (max-width: 700px) 100vw, (-webkit-min-device-pixel-ratio: 2) and (max-width: 700px) 100vw, 700px" data-testid="og" /><img data-recalc-dims="1" fetchpriority="high" decoding="async" class="bh lf nj c" role="presentation" src="https://i0.wp.com/miro.medium.com/v2/resize%3Afit%3A700/1%2AJkBf-4djpgm6yQZo37hAvg.png?resize=640%2C288&#038;ssl=1" alt="" width="640" height="288" /></picture></div>
</div>
</figure>
<p id="4b9a" class="pw-post-body-paragraph lx ly go lz b ma mb mc md me mf mg mh mi mj mk ml mm mn mo mp mq mr ms mt mu gh bk" data-selectable-paragraph="">A second technic we used was to run the URL via VirusTotal to get the Hash:</p>
<figure class="mz na nb nc nd ne mw mx paragraph-image">
<div class="nf ng fd nh bh ni" tabindex="0" role="button">
<div class="mw mx nk"><picture><source srcset="https://miro.medium.com/v2/resize:fit:640/format:webp/1*6gzj_Rm-T6itik0fJalv3g.png 640w, https://miro.medium.com/v2/resize:fit:720/format:webp/1*6gzj_Rm-T6itik0fJalv3g.png 720w, https://miro.medium.com/v2/resize:fit:750/format:webp/1*6gzj_Rm-T6itik0fJalv3g.png 750w, https://miro.medium.com/v2/resize:fit:786/format:webp/1*6gzj_Rm-T6itik0fJalv3g.png 786w, https://miro.medium.com/v2/resize:fit:828/format:webp/1*6gzj_Rm-T6itik0fJalv3g.png 828w, https://miro.medium.com/v2/resize:fit:1100/format:webp/1*6gzj_Rm-T6itik0fJalv3g.png 1100w, https://miro.medium.com/v2/resize:fit:1400/format:webp/1*6gzj_Rm-T6itik0fJalv3g.png 1400w" type="image/webp" sizes="(min-resolution: 4dppx) and (max-width: 700px) 50vw, (-webkit-min-device-pixel-ratio: 4) and (max-width: 700px) 50vw, (min-resolution: 3dppx) and (max-width: 700px) 67vw, (-webkit-min-device-pixel-ratio: 3) and (max-width: 700px) 65vw, (min-resolution: 2.5dppx) and (max-width: 700px) 80vw, (-webkit-min-device-pixel-ratio: 2.5) and (max-width: 700px) 80vw, (min-resolution: 2dppx) and (max-width: 700px) 100vw, (-webkit-min-device-pixel-ratio: 2) and (max-width: 700px) 100vw, 700px" /><source srcset="https://miro.medium.com/v2/resize:fit:640/1*6gzj_Rm-T6itik0fJalv3g.png 640w, https://miro.medium.com/v2/resize:fit:720/1*6gzj_Rm-T6itik0fJalv3g.png 720w, https://miro.medium.com/v2/resize:fit:750/1*6gzj_Rm-T6itik0fJalv3g.png 750w, https://miro.medium.com/v2/resize:fit:786/1*6gzj_Rm-T6itik0fJalv3g.png 786w, https://miro.medium.com/v2/resize:fit:828/1*6gzj_Rm-T6itik0fJalv3g.png 828w, https://miro.medium.com/v2/resize:fit:1100/1*6gzj_Rm-T6itik0fJalv3g.png 1100w, https://miro.medium.com/v2/resize:fit:1400/1*6gzj_Rm-T6itik0fJalv3g.png 1400w" sizes="(min-resolution: 4dppx) and (max-width: 700px) 50vw, (-webkit-min-device-pixel-ratio: 4) and (max-width: 700px) 50vw, (min-resolution: 3dppx) and (max-width: 700px) 67vw, (-webkit-min-device-pixel-ratio: 3) and (max-width: 700px) 65vw, (min-resolution: 2.5dppx) and (max-width: 700px) 80vw, (-webkit-min-device-pixel-ratio: 2.5) and (max-width: 700px) 80vw, (min-resolution: 2dppx) and (max-width: 700px) 100vw, (-webkit-min-device-pixel-ratio: 2) and (max-width: 700px) 100vw, 700px" data-testid="og" /><img data-recalc-dims="1" decoding="async" class="bh lf nj c" role="presentation" src="https://i0.wp.com/miro.medium.com/v2/resize%3Afit%3A700/1%2A6gzj_Rm-T6itik0fJalv3g.png?resize=640%2C326&#038;ssl=1" alt="" width="640" height="326" /></picture></div>
</div>
</figure>
<figure class="mz na nb nc nd ne mw mx paragraph-image">
<div class="nf ng fd nh bh ni" tabindex="0" role="button">
<div class="mw mx nl"><picture><source srcset="https://miro.medium.com/v2/resize:fit:640/format:webp/1*d6XeKbBhFkr--G2WHd3A9A.png 640w, https://miro.medium.com/v2/resize:fit:720/format:webp/1*d6XeKbBhFkr--G2WHd3A9A.png 720w, https://miro.medium.com/v2/resize:fit:750/format:webp/1*d6XeKbBhFkr--G2WHd3A9A.png 750w, https://miro.medium.com/v2/resize:fit:786/format:webp/1*d6XeKbBhFkr--G2WHd3A9A.png 786w, https://miro.medium.com/v2/resize:fit:828/format:webp/1*d6XeKbBhFkr--G2WHd3A9A.png 828w, https://miro.medium.com/v2/resize:fit:1100/format:webp/1*d6XeKbBhFkr--G2WHd3A9A.png 1100w, https://miro.medium.com/v2/resize:fit:1400/format:webp/1*d6XeKbBhFkr--G2WHd3A9A.png 1400w" type="image/webp" sizes="(min-resolution: 4dppx) and (max-width: 700px) 50vw, (-webkit-min-device-pixel-ratio: 4) and (max-width: 700px) 50vw, (min-resolution: 3dppx) and (max-width: 700px) 67vw, (-webkit-min-device-pixel-ratio: 3) and (max-width: 700px) 65vw, (min-resolution: 2.5dppx) and (max-width: 700px) 80vw, (-webkit-min-device-pixel-ratio: 2.5) and (max-width: 700px) 80vw, (min-resolution: 2dppx) and (max-width: 700px) 100vw, (-webkit-min-device-pixel-ratio: 2) and (max-width: 700px) 100vw, 700px" /><source srcset="https://miro.medium.com/v2/resize:fit:640/1*d6XeKbBhFkr--G2WHd3A9A.png 640w, https://miro.medium.com/v2/resize:fit:720/1*d6XeKbBhFkr--G2WHd3A9A.png 720w, https://miro.medium.com/v2/resize:fit:750/1*d6XeKbBhFkr--G2WHd3A9A.png 750w, https://miro.medium.com/v2/resize:fit:786/1*d6XeKbBhFkr--G2WHd3A9A.png 786w, https://miro.medium.com/v2/resize:fit:828/1*d6XeKbBhFkr--G2WHd3A9A.png 828w, https://miro.medium.com/v2/resize:fit:1100/1*d6XeKbBhFkr--G2WHd3A9A.png 1100w, https://miro.medium.com/v2/resize:fit:1400/1*d6XeKbBhFkr--G2WHd3A9A.png 1400w" sizes="(min-resolution: 4dppx) and (max-width: 700px) 50vw, (-webkit-min-device-pixel-ratio: 4) and (max-width: 700px) 50vw, (min-resolution: 3dppx) and (max-width: 700px) 67vw, (-webkit-min-device-pixel-ratio: 3) and (max-width: 700px) 65vw, (min-resolution: 2.5dppx) and (max-width: 700px) 80vw, (-webkit-min-device-pixel-ratio: 2.5) and (max-width: 700px) 80vw, (min-resolution: 2dppx) and (max-width: 700px) 100vw, (-webkit-min-device-pixel-ratio: 2) and (max-width: 700px) 100vw, 700px" data-testid="og" /><img data-recalc-dims="1" decoding="async" class="bh lf nj c" role="presentation" src="https://i0.wp.com/miro.medium.com/v2/resize%3Afit%3A700/1%2Ad6XeKbBhFkr--G2WHd3A9A.png?resize=640%2C389&#038;ssl=1" alt="" width="640" height="389" /></picture></div>
</div>
</figure>
<p id="7449" class="pw-post-body-paragraph lx ly go lz b ma mb mc md me mf mg mh mi mj mk ml mm mn mo mp mq mr ms mt mu gh bk" data-selectable-paragraph="">We got the same hash as we got from URLSCAN:</p>
<figure class="mz na nb nc nd ne mw mx paragraph-image">
<div class="nf ng fd nh bh ni" tabindex="0" role="button">
<div class="mw mx nm"><picture><source srcset="https://miro.medium.com/v2/resize:fit:640/format:webp/1*Hs1bpoLOspAjFGObYbF9Fg.png 640w, https://miro.medium.com/v2/resize:fit:720/format:webp/1*Hs1bpoLOspAjFGObYbF9Fg.png 720w, https://miro.medium.com/v2/resize:fit:750/format:webp/1*Hs1bpoLOspAjFGObYbF9Fg.png 750w, https://miro.medium.com/v2/resize:fit:786/format:webp/1*Hs1bpoLOspAjFGObYbF9Fg.png 786w, https://miro.medium.com/v2/resize:fit:828/format:webp/1*Hs1bpoLOspAjFGObYbF9Fg.png 828w, https://miro.medium.com/v2/resize:fit:1100/format:webp/1*Hs1bpoLOspAjFGObYbF9Fg.png 1100w, https://miro.medium.com/v2/resize:fit:1400/format:webp/1*Hs1bpoLOspAjFGObYbF9Fg.png 1400w" type="image/webp" sizes="(min-resolution: 4dppx) and (max-width: 700px) 50vw, (-webkit-min-device-pixel-ratio: 4) and (max-width: 700px) 50vw, (min-resolution: 3dppx) and (max-width: 700px) 67vw, (-webkit-min-device-pixel-ratio: 3) and (max-width: 700px) 65vw, (min-resolution: 2.5dppx) and (max-width: 700px) 80vw, (-webkit-min-device-pixel-ratio: 2.5) and (max-width: 700px) 80vw, (min-resolution: 2dppx) and (max-width: 700px) 100vw, (-webkit-min-device-pixel-ratio: 2) and (max-width: 700px) 100vw, 700px" /><source srcset="https://miro.medium.com/v2/resize:fit:640/1*Hs1bpoLOspAjFGObYbF9Fg.png 640w, https://miro.medium.com/v2/resize:fit:720/1*Hs1bpoLOspAjFGObYbF9Fg.png 720w, https://miro.medium.com/v2/resize:fit:750/1*Hs1bpoLOspAjFGObYbF9Fg.png 750w, https://miro.medium.com/v2/resize:fit:786/1*Hs1bpoLOspAjFGObYbF9Fg.png 786w, https://miro.medium.com/v2/resize:fit:828/1*Hs1bpoLOspAjFGObYbF9Fg.png 828w, https://miro.medium.com/v2/resize:fit:1100/1*Hs1bpoLOspAjFGObYbF9Fg.png 1100w, https://miro.medium.com/v2/resize:fit:1400/1*Hs1bpoLOspAjFGObYbF9Fg.png 1400w" sizes="(min-resolution: 4dppx) and (max-width: 700px) 50vw, (-webkit-min-device-pixel-ratio: 4) and (max-width: 700px) 50vw, (min-resolution: 3dppx) and (max-width: 700px) 67vw, (-webkit-min-device-pixel-ratio: 3) and (max-width: 700px) 65vw, (min-resolution: 2.5dppx) and (max-width: 700px) 80vw, (-webkit-min-device-pixel-ratio: 2.5) and (max-width: 700px) 80vw, (min-resolution: 2dppx) and (max-width: 700px) 100vw, (-webkit-min-device-pixel-ratio: 2) and (max-width: 700px) 100vw, 700px" data-testid="og" /><img data-recalc-dims="1" loading="lazy" decoding="async" class="bh lf nj c" role="presentation" src="https://i0.wp.com/miro.medium.com/v2/resize%3Afit%3A700/1%2AHs1bpoLOspAjFGObYbF9Fg.png?resize=640%2C275&#038;ssl=1" alt="" width="640" height="275" /></picture></div>
</div>
</figure>
<p id="9b1f" class="pw-post-body-paragraph lx ly go lz b ma mb mc md me mf mg mh mi mj mk ml mm mn mo mp mq mr ms mt mu gh bk" data-selectable-paragraph="">As you may know, Censys ( Censys Search will <strong class="lz gp">end on March 31, 2025</strong>) is one of the best tool to get more details about an IP address. Using Censys, we got:</p>
<p id="362f" class="pw-post-body-paragraph lx ly go lz b ma mb mc md me mf mg mh mi mj mk ml mm mn mo mp mq mr ms mt mu gh bk" data-selectable-paragraph=""><a class="ag mv" href="https://search.censys.io/hosts/192.159.99.10?resource=hosts&amp;sort=RELEVANCE&amp;per_page=25&amp;virtual_hosts=EXCLUDE&amp;q=ScreenConnect%2F23.2.9.8466-310111362&amp;at_time=2025-03-19T08%3A13%3A01.950Z" target="_blank" rel="noopener ugc nofollow">192.159.99.10 — Host Summary — Censys</a></p>
<p id="9acd" class="pw-post-body-paragraph lx ly go lz b ma mb mc md me mf mg mh mi mj mk ml mm mn mo mp mq mr ms mt mu gh bk" data-selectable-paragraph="">The unique IP 192.159.99.10 link to the domain in question:</p>
<figure class="mz na nb nc nd ne mw mx paragraph-image">
<div class="nf ng fd nh bh ni" tabindex="0" role="button">
<div class="mw mx nn"><picture><source srcset="https://miro.medium.com/v2/resize:fit:640/format:webp/1*SE9cTWsdj4sc8AkZjhIWgw.png 640w, https://miro.medium.com/v2/resize:fit:720/format:webp/1*SE9cTWsdj4sc8AkZjhIWgw.png 720w, https://miro.medium.com/v2/resize:fit:750/format:webp/1*SE9cTWsdj4sc8AkZjhIWgw.png 750w, https://miro.medium.com/v2/resize:fit:786/format:webp/1*SE9cTWsdj4sc8AkZjhIWgw.png 786w, https://miro.medium.com/v2/resize:fit:828/format:webp/1*SE9cTWsdj4sc8AkZjhIWgw.png 828w, https://miro.medium.com/v2/resize:fit:1100/format:webp/1*SE9cTWsdj4sc8AkZjhIWgw.png 1100w, https://miro.medium.com/v2/resize:fit:1400/format:webp/1*SE9cTWsdj4sc8AkZjhIWgw.png 1400w" type="image/webp" sizes="(min-resolution: 4dppx) and (max-width: 700px) 50vw, (-webkit-min-device-pixel-ratio: 4) and (max-width: 700px) 50vw, (min-resolution: 3dppx) and (max-width: 700px) 67vw, (-webkit-min-device-pixel-ratio: 3) and (max-width: 700px) 65vw, (min-resolution: 2.5dppx) and (max-width: 700px) 80vw, (-webkit-min-device-pixel-ratio: 2.5) and (max-width: 700px) 80vw, (min-resolution: 2dppx) and (max-width: 700px) 100vw, (-webkit-min-device-pixel-ratio: 2) and (max-width: 700px) 100vw, 700px" /><source srcset="https://miro.medium.com/v2/resize:fit:640/1*SE9cTWsdj4sc8AkZjhIWgw.png 640w, https://miro.medium.com/v2/resize:fit:720/1*SE9cTWsdj4sc8AkZjhIWgw.png 720w, https://miro.medium.com/v2/resize:fit:750/1*SE9cTWsdj4sc8AkZjhIWgw.png 750w, https://miro.medium.com/v2/resize:fit:786/1*SE9cTWsdj4sc8AkZjhIWgw.png 786w, https://miro.medium.com/v2/resize:fit:828/1*SE9cTWsdj4sc8AkZjhIWgw.png 828w, https://miro.medium.com/v2/resize:fit:1100/1*SE9cTWsdj4sc8AkZjhIWgw.png 1100w, https://miro.medium.com/v2/resize:fit:1400/1*SE9cTWsdj4sc8AkZjhIWgw.png 1400w" sizes="(min-resolution: 4dppx) and (max-width: 700px) 50vw, (-webkit-min-device-pixel-ratio: 4) and (max-width: 700px) 50vw, (min-resolution: 3dppx) and (max-width: 700px) 67vw, (-webkit-min-device-pixel-ratio: 3) and (max-width: 700px) 65vw, (min-resolution: 2.5dppx) and (max-width: 700px) 80vw, (-webkit-min-device-pixel-ratio: 2.5) and (max-width: 700px) 80vw, (min-resolution: 2dppx) and (max-width: 700px) 100vw, (-webkit-min-device-pixel-ratio: 2) and (max-width: 700px) 100vw, 700px" data-testid="og" /><img data-recalc-dims="1" loading="lazy" decoding="async" class="bh lf nj c" role="presentation" src="https://i0.wp.com/miro.medium.com/v2/resize%3Afit%3A700/1%2ASE9cTWsdj4sc8AkZjhIWgw.png?resize=640%2C335&#038;ssl=1" alt="" width="640" height="335" /></picture></div>
</div>
</figure>
<p id="d636" class="pw-post-body-paragraph lx ly go lz b ma mb mc md me mf mg mh mi mj mk ml mm mn mo mp mq mr ms mt mu gh bk" data-selectable-paragraph="">On the port HTTP 443, a romote access ConnectWise Control 23.2.9.8466 is available.</p>
<figure class="mz na nb nc nd ne mw mx paragraph-image">
<div class="nf ng fd nh bh ni" tabindex="0" role="button">
<div class="mw mx no"><picture><source srcset="https://miro.medium.com/v2/resize:fit:640/format:webp/1*JfJzUAahoBXRr-hWLLj2_Q.png 640w, https://miro.medium.com/v2/resize:fit:720/format:webp/1*JfJzUAahoBXRr-hWLLj2_Q.png 720w, https://miro.medium.com/v2/resize:fit:750/format:webp/1*JfJzUAahoBXRr-hWLLj2_Q.png 750w, https://miro.medium.com/v2/resize:fit:786/format:webp/1*JfJzUAahoBXRr-hWLLj2_Q.png 786w, https://miro.medium.com/v2/resize:fit:828/format:webp/1*JfJzUAahoBXRr-hWLLj2_Q.png 828w, https://miro.medium.com/v2/resize:fit:1100/format:webp/1*JfJzUAahoBXRr-hWLLj2_Q.png 1100w, https://miro.medium.com/v2/resize:fit:1400/format:webp/1*JfJzUAahoBXRr-hWLLj2_Q.png 1400w" type="image/webp" sizes="(min-resolution: 4dppx) and (max-width: 700px) 50vw, (-webkit-min-device-pixel-ratio: 4) and (max-width: 700px) 50vw, (min-resolution: 3dppx) and (max-width: 700px) 67vw, (-webkit-min-device-pixel-ratio: 3) and (max-width: 700px) 65vw, (min-resolution: 2.5dppx) and (max-width: 700px) 80vw, (-webkit-min-device-pixel-ratio: 2.5) and (max-width: 700px) 80vw, (min-resolution: 2dppx) and (max-width: 700px) 100vw, (-webkit-min-device-pixel-ratio: 2) and (max-width: 700px) 100vw, 700px" /><source srcset="https://miro.medium.com/v2/resize:fit:640/1*JfJzUAahoBXRr-hWLLj2_Q.png 640w, https://miro.medium.com/v2/resize:fit:720/1*JfJzUAahoBXRr-hWLLj2_Q.png 720w, https://miro.medium.com/v2/resize:fit:750/1*JfJzUAahoBXRr-hWLLj2_Q.png 750w, https://miro.medium.com/v2/resize:fit:786/1*JfJzUAahoBXRr-hWLLj2_Q.png 786w, https://miro.medium.com/v2/resize:fit:828/1*JfJzUAahoBXRr-hWLLj2_Q.png 828w, https://miro.medium.com/v2/resize:fit:1100/1*JfJzUAahoBXRr-hWLLj2_Q.png 1100w, https://miro.medium.com/v2/resize:fit:1400/1*JfJzUAahoBXRr-hWLLj2_Q.png 1400w" sizes="(min-resolution: 4dppx) and (max-width: 700px) 50vw, (-webkit-min-device-pixel-ratio: 4) and (max-width: 700px) 50vw, (min-resolution: 3dppx) and (max-width: 700px) 67vw, (-webkit-min-device-pixel-ratio: 3) and (max-width: 700px) 65vw, (min-resolution: 2.5dppx) and (max-width: 700px) 80vw, (-webkit-min-device-pixel-ratio: 2.5) and (max-width: 700px) 80vw, (min-resolution: 2dppx) and (max-width: 700px) 100vw, (-webkit-min-device-pixel-ratio: 2) and (max-width: 700px) 100vw, 700px" data-testid="og" /><img data-recalc-dims="1" loading="lazy" decoding="async" class="bh lf nj c" role="presentation" src="https://i0.wp.com/miro.medium.com/v2/resize%3Afit%3A700/1%2AJfJzUAahoBXRr-hWLLj2_Q.png?resize=640%2C246&#038;ssl=1" alt="" width="640" height="246" /></picture></div>
</div>
</figure>
<p id="0ed3" class="pw-post-body-paragraph lx ly go lz b ma mb mc md me mf mg mh mi mj mk ml mm mn mo mp mq mr ms mt mu gh bk" data-selectable-paragraph="">We decided to run the executable file through app any run to be able to analyse it in the sandbox: <a class="ag mv" href="https://app.any.run/browses/78c73b3d-b38e-48cd-813e-9d4b1883cb0c" target="_blank" rel="noopener ugc nofollow">https://app.any.run/browses/78c73b3d-b38e-48cd-813e-9d4b1883cb0c</a></p>
<figure class="mz na nb nc nd ne mw mx paragraph-image">
<div class="nf ng fd nh bh ni" tabindex="0" role="button">
<div class="mw mx np"><picture><source srcset="https://miro.medium.com/v2/resize:fit:640/format:webp/1*5A5FIMtgMKg2oiV92ETnYA.png 640w, https://miro.medium.com/v2/resize:fit:720/format:webp/1*5A5FIMtgMKg2oiV92ETnYA.png 720w, https://miro.medium.com/v2/resize:fit:750/format:webp/1*5A5FIMtgMKg2oiV92ETnYA.png 750w, https://miro.medium.com/v2/resize:fit:786/format:webp/1*5A5FIMtgMKg2oiV92ETnYA.png 786w, https://miro.medium.com/v2/resize:fit:828/format:webp/1*5A5FIMtgMKg2oiV92ETnYA.png 828w, https://miro.medium.com/v2/resize:fit:1100/format:webp/1*5A5FIMtgMKg2oiV92ETnYA.png 1100w, https://miro.medium.com/v2/resize:fit:1400/format:webp/1*5A5FIMtgMKg2oiV92ETnYA.png 1400w" type="image/webp" sizes="(min-resolution: 4dppx) and (max-width: 700px) 50vw, (-webkit-min-device-pixel-ratio: 4) and (max-width: 700px) 50vw, (min-resolution: 3dppx) and (max-width: 700px) 67vw, (-webkit-min-device-pixel-ratio: 3) and (max-width: 700px) 65vw, (min-resolution: 2.5dppx) and (max-width: 700px) 80vw, (-webkit-min-device-pixel-ratio: 2.5) and (max-width: 700px) 80vw, (min-resolution: 2dppx) and (max-width: 700px) 100vw, (-webkit-min-device-pixel-ratio: 2) and (max-width: 700px) 100vw, 700px" /><source srcset="https://miro.medium.com/v2/resize:fit:640/1*5A5FIMtgMKg2oiV92ETnYA.png 640w, https://miro.medium.com/v2/resize:fit:720/1*5A5FIMtgMKg2oiV92ETnYA.png 720w, https://miro.medium.com/v2/resize:fit:750/1*5A5FIMtgMKg2oiV92ETnYA.png 750w, https://miro.medium.com/v2/resize:fit:786/1*5A5FIMtgMKg2oiV92ETnYA.png 786w, https://miro.medium.com/v2/resize:fit:828/1*5A5FIMtgMKg2oiV92ETnYA.png 828w, https://miro.medium.com/v2/resize:fit:1100/1*5A5FIMtgMKg2oiV92ETnYA.png 1100w, https://miro.medium.com/v2/resize:fit:1400/1*5A5FIMtgMKg2oiV92ETnYA.png 1400w" sizes="(min-resolution: 4dppx) and (max-width: 700px) 50vw, (-webkit-min-device-pixel-ratio: 4) and (max-width: 700px) 50vw, (min-resolution: 3dppx) and (max-width: 700px) 67vw, (-webkit-min-device-pixel-ratio: 3) and (max-width: 700px) 65vw, (min-resolution: 2.5dppx) and (max-width: 700px) 80vw, (-webkit-min-device-pixel-ratio: 2.5) and (max-width: 700px) 80vw, (min-resolution: 2dppx) and (max-width: 700px) 100vw, (-webkit-min-device-pixel-ratio: 2) and (max-width: 700px) 100vw, 700px" data-testid="og" /><img data-recalc-dims="1" loading="lazy" decoding="async" class="bh lf nj c" role="presentation" src="https://i0.wp.com/miro.medium.com/v2/resize%3Afit%3A700/1%2A5A5FIMtgMKg2oiV92ETnYA.png?resize=640%2C283&#038;ssl=1" alt="" width="640" height="283" /></picture></div>
</div>
</figure>
<p id="0ef9" class="pw-post-body-paragraph lx ly go lz b ma mb mc md me mf mg mh mi mj mk ml mm mn mo mp mq mr ms mt mu gh bk" data-selectable-paragraph="">After running the executable file, we found out that the file is digitally signed by ConnectWise LLC since 2023. Which look strange but possible.</p>
<p id="282d" class="pw-post-body-paragraph lx ly go lz b ma mb mc md me mf mg mh mi mj mk ml mm mn mo mp mq mr ms mt mu gh bk" data-selectable-paragraph="">While analysing the executable file, we found one interesintg indicator</p>
<figure class="mz na nb nc nd ne mw mx paragraph-image">
<div class="nf ng fd nh bh ni" tabindex="0" role="button">
<div class="mw mx nq"><picture><source srcset="https://miro.medium.com/v2/resize:fit:640/format:webp/1*N6V8_Bmw2RWQuLDToVVz4w.png 640w, https://miro.medium.com/v2/resize:fit:720/format:webp/1*N6V8_Bmw2RWQuLDToVVz4w.png 720w, https://miro.medium.com/v2/resize:fit:750/format:webp/1*N6V8_Bmw2RWQuLDToVVz4w.png 750w, https://miro.medium.com/v2/resize:fit:786/format:webp/1*N6V8_Bmw2RWQuLDToVVz4w.png 786w, https://miro.medium.com/v2/resize:fit:828/format:webp/1*N6V8_Bmw2RWQuLDToVVz4w.png 828w, https://miro.medium.com/v2/resize:fit:1100/format:webp/1*N6V8_Bmw2RWQuLDToVVz4w.png 1100w, https://miro.medium.com/v2/resize:fit:1400/format:webp/1*N6V8_Bmw2RWQuLDToVVz4w.png 1400w" type="image/webp" sizes="(min-resolution: 4dppx) and (max-width: 700px) 50vw, (-webkit-min-device-pixel-ratio: 4) and (max-width: 700px) 50vw, (min-resolution: 3dppx) and (max-width: 700px) 67vw, (-webkit-min-device-pixel-ratio: 3) and (max-width: 700px) 65vw, (min-resolution: 2.5dppx) and (max-width: 700px) 80vw, (-webkit-min-device-pixel-ratio: 2.5) and (max-width: 700px) 80vw, (min-resolution: 2dppx) and (max-width: 700px) 100vw, (-webkit-min-device-pixel-ratio: 2) and (max-width: 700px) 100vw, 700px" /><source srcset="https://miro.medium.com/v2/resize:fit:640/1*N6V8_Bmw2RWQuLDToVVz4w.png 640w, https://miro.medium.com/v2/resize:fit:720/1*N6V8_Bmw2RWQuLDToVVz4w.png 720w, https://miro.medium.com/v2/resize:fit:750/1*N6V8_Bmw2RWQuLDToVVz4w.png 750w, https://miro.medium.com/v2/resize:fit:786/1*N6V8_Bmw2RWQuLDToVVz4w.png 786w, https://miro.medium.com/v2/resize:fit:828/1*N6V8_Bmw2RWQuLDToVVz4w.png 828w, https://miro.medium.com/v2/resize:fit:1100/1*N6V8_Bmw2RWQuLDToVVz4w.png 1100w, https://miro.medium.com/v2/resize:fit:1400/1*N6V8_Bmw2RWQuLDToVVz4w.png 1400w" sizes="(min-resolution: 4dppx) and (max-width: 700px) 50vw, (-webkit-min-device-pixel-ratio: 4) and (max-width: 700px) 50vw, (min-resolution: 3dppx) and (max-width: 700px) 67vw, (-webkit-min-device-pixel-ratio: 3) and (max-width: 700px) 65vw, (min-resolution: 2.5dppx) and (max-width: 700px) 80vw, (-webkit-min-device-pixel-ratio: 2.5) and (max-width: 700px) 80vw, (min-resolution: 2dppx) and (max-width: 700px) 100vw, (-webkit-min-device-pixel-ratio: 2) and (max-width: 700px) 100vw, 700px" data-testid="og" /><img data-recalc-dims="1" loading="lazy" decoding="async" class="bh lf nj c" role="presentation" src="https://i0.wp.com/miro.medium.com/v2/resize%3Afit%3A700/1%2AN6V8_Bmw2RWQuLDToVVz4w.png?resize=640%2C378&#038;ssl=1" alt="" width="640" height="378" /></picture></div>
</div>
</figure>
<p id="8a8c" class="pw-post-body-paragraph lx ly go lz b ma mb mc md me mf mg mh mi mj mk ml mm mn mo mp mq mr ms mt mu gh bk" data-selectable-paragraph="">The file name : C:\Users\jmorgan\Source\cwcontrol\Misc\Bootstrapper\Release\ClickOnceRunner.pdb</p>
<p id="1a5d" class="pw-post-body-paragraph lx ly go lz b ma mb mc md me mf mg mh mi mj mk ml mm mn mo mp mq mr ms mt mu gh bk" data-selectable-paragraph="">following the ImportsHash: 7631a79a9071099fa4803e1c4c5df207</p>
<p id="110f" class="pw-post-body-paragraph lx ly go lz b ma mb mc md me mf mg mh mi mj mk ml mm mn mo mp mq mr ms mt mu gh bk" data-selectable-paragraph="">We found out that the Hash of the file is quite famous through Google search:</p>
<figure class="mz na nb nc nd ne mw mx paragraph-image">
<div class="nf ng fd nh bh ni" tabindex="0" role="button">
<div class="mw mx nr"><picture><source srcset="https://miro.medium.com/v2/resize:fit:640/format:webp/1*4rXUuBJg6_jOPSOCQMdpbQ.png 640w, https://miro.medium.com/v2/resize:fit:720/format:webp/1*4rXUuBJg6_jOPSOCQMdpbQ.png 720w, https://miro.medium.com/v2/resize:fit:750/format:webp/1*4rXUuBJg6_jOPSOCQMdpbQ.png 750w, https://miro.medium.com/v2/resize:fit:786/format:webp/1*4rXUuBJg6_jOPSOCQMdpbQ.png 786w, https://miro.medium.com/v2/resize:fit:828/format:webp/1*4rXUuBJg6_jOPSOCQMdpbQ.png 828w, https://miro.medium.com/v2/resize:fit:1100/format:webp/1*4rXUuBJg6_jOPSOCQMdpbQ.png 1100w, https://miro.medium.com/v2/resize:fit:1400/format:webp/1*4rXUuBJg6_jOPSOCQMdpbQ.png 1400w" type="image/webp" sizes="(min-resolution: 4dppx) and (max-width: 700px) 50vw, (-webkit-min-device-pixel-ratio: 4) and (max-width: 700px) 50vw, (min-resolution: 3dppx) and (max-width: 700px) 67vw, (-webkit-min-device-pixel-ratio: 3) and (max-width: 700px) 65vw, (min-resolution: 2.5dppx) and (max-width: 700px) 80vw, (-webkit-min-device-pixel-ratio: 2.5) and (max-width: 700px) 80vw, (min-resolution: 2dppx) and (max-width: 700px) 100vw, (-webkit-min-device-pixel-ratio: 2) and (max-width: 700px) 100vw, 700px" /><source srcset="https://miro.medium.com/v2/resize:fit:640/1*4rXUuBJg6_jOPSOCQMdpbQ.png 640w, https://miro.medium.com/v2/resize:fit:720/1*4rXUuBJg6_jOPSOCQMdpbQ.png 720w, https://miro.medium.com/v2/resize:fit:750/1*4rXUuBJg6_jOPSOCQMdpbQ.png 750w, https://miro.medium.com/v2/resize:fit:786/1*4rXUuBJg6_jOPSOCQMdpbQ.png 786w, https://miro.medium.com/v2/resize:fit:828/1*4rXUuBJg6_jOPSOCQMdpbQ.png 828w, https://miro.medium.com/v2/resize:fit:1100/1*4rXUuBJg6_jOPSOCQMdpbQ.png 1100w, https://miro.medium.com/v2/resize:fit:1400/1*4rXUuBJg6_jOPSOCQMdpbQ.png 1400w" sizes="(min-resolution: 4dppx) and (max-width: 700px) 50vw, (-webkit-min-device-pixel-ratio: 4) and (max-width: 700px) 50vw, (min-resolution: 3dppx) and (max-width: 700px) 67vw, (-webkit-min-device-pixel-ratio: 3) and (max-width: 700px) 65vw, (min-resolution: 2.5dppx) and (max-width: 700px) 80vw, (-webkit-min-device-pixel-ratio: 2.5) and (max-width: 700px) 80vw, (min-resolution: 2dppx) and (max-width: 700px) 100vw, (-webkit-min-device-pixel-ratio: 2) and (max-width: 700px) 100vw, 700px" data-testid="og" /><img data-recalc-dims="1" loading="lazy" decoding="async" class="bh lf nj c" role="presentation" src="https://i0.wp.com/miro.medium.com/v2/resize%3Afit%3A700/1%2A4rXUuBJg6_jOPSOCQMdpbQ.png?resize=640%2C349&#038;ssl=1" alt="" width="640" height="349" /></picture></div>
</div>
</figure>
<figure class="mz na nb nc nd ne mw mx paragraph-image">
<div class="nf ng fd nh bh ni" tabindex="0" role="button">
<div class="mw mx ns"><picture><source srcset="https://miro.medium.com/v2/resize:fit:640/format:webp/1*fKIKOwzF2AapSs4l2LZB4Q.png 640w, https://miro.medium.com/v2/resize:fit:720/format:webp/1*fKIKOwzF2AapSs4l2LZB4Q.png 720w, https://miro.medium.com/v2/resize:fit:750/format:webp/1*fKIKOwzF2AapSs4l2LZB4Q.png 750w, https://miro.medium.com/v2/resize:fit:786/format:webp/1*fKIKOwzF2AapSs4l2LZB4Q.png 786w, https://miro.medium.com/v2/resize:fit:828/format:webp/1*fKIKOwzF2AapSs4l2LZB4Q.png 828w, https://miro.medium.com/v2/resize:fit:1100/format:webp/1*fKIKOwzF2AapSs4l2LZB4Q.png 1100w, https://miro.medium.com/v2/resize:fit:1400/format:webp/1*fKIKOwzF2AapSs4l2LZB4Q.png 1400w" type="image/webp" sizes="(min-resolution: 4dppx) and (max-width: 700px) 50vw, (-webkit-min-device-pixel-ratio: 4) and (max-width: 700px) 50vw, (min-resolution: 3dppx) and (max-width: 700px) 67vw, (-webkit-min-device-pixel-ratio: 3) and (max-width: 700px) 65vw, (min-resolution: 2.5dppx) and (max-width: 700px) 80vw, (-webkit-min-device-pixel-ratio: 2.5) and (max-width: 700px) 80vw, (min-resolution: 2dppx) and (max-width: 700px) 100vw, (-webkit-min-device-pixel-ratio: 2) and (max-width: 700px) 100vw, 700px" /><source srcset="https://miro.medium.com/v2/resize:fit:640/1*fKIKOwzF2AapSs4l2LZB4Q.png 640w, https://miro.medium.com/v2/resize:fit:720/1*fKIKOwzF2AapSs4l2LZB4Q.png 720w, https://miro.medium.com/v2/resize:fit:750/1*fKIKOwzF2AapSs4l2LZB4Q.png 750w, https://miro.medium.com/v2/resize:fit:786/1*fKIKOwzF2AapSs4l2LZB4Q.png 786w, https://miro.medium.com/v2/resize:fit:828/1*fKIKOwzF2AapSs4l2LZB4Q.png 828w, https://miro.medium.com/v2/resize:fit:1100/1*fKIKOwzF2AapSs4l2LZB4Q.png 1100w, https://miro.medium.com/v2/resize:fit:1400/1*fKIKOwzF2AapSs4l2LZB4Q.png 1400w" sizes="(min-resolution: 4dppx) and (max-width: 700px) 50vw, (-webkit-min-device-pixel-ratio: 4) and (max-width: 700px) 50vw, (min-resolution: 3dppx) and (max-width: 700px) 67vw, (-webkit-min-device-pixel-ratio: 3) and (max-width: 700px) 65vw, (min-resolution: 2.5dppx) and (max-width: 700px) 80vw, (-webkit-min-device-pixel-ratio: 2.5) and (max-width: 700px) 80vw, (min-resolution: 2dppx) and (max-width: 700px) 100vw, (-webkit-min-device-pixel-ratio: 2) and (max-width: 700px) 100vw, 700px" data-testid="og" /><img data-recalc-dims="1" loading="lazy" decoding="async" class="bh lf nj c" role="presentation" src="https://i0.wp.com/miro.medium.com/v2/resize%3Afit%3A700/1%2AfKIKOwzF2AapSs4l2LZB4Q.png?resize=640%2C389&#038;ssl=1" alt="" width="640" height="389" /></picture></div>
</div>
</figure>
<p id="df16" class="pw-post-body-paragraph lx ly go lz b ma mb mc md me mf mg mh mi mj mk ml mm mn mo mp mq mr ms mt mu gh bk" data-selectable-paragraph="">By checking the information from: <a class="ag mv" href="https://bazaar.abuse.ch/sample/d4b396874b63841713f83aecb7b3bf6e19b068f246c950cbdbb08bdafb394763/" target="_blank" rel="noopener ugc nofollow">MalwareBazaar | SHA256 d4b396874b63841713f83aecb7b3bf6e19b068f246c950cbdbb08bdafb394763 (ConnectWise)</a></p>
<p id="d45d" class="pw-post-body-paragraph lx ly go lz b ma mb mc md me mf mg mh mi mj mk ml mm mn mo mp mq mr ms mt mu gh bk" data-selectable-paragraph="">We found very interesting details</p>
<figure class="mz na nb nc nd ne mw mx paragraph-image">
<div class="nf ng fd nh bh ni" tabindex="0" role="button">
<div class="mw mx nt"><picture><source srcset="https://miro.medium.com/v2/resize:fit:640/format:webp/1*64N0_Nv61JtkHJu5b5T4Pw.png 640w, https://miro.medium.com/v2/resize:fit:720/format:webp/1*64N0_Nv61JtkHJu5b5T4Pw.png 720w, https://miro.medium.com/v2/resize:fit:750/format:webp/1*64N0_Nv61JtkHJu5b5T4Pw.png 750w, https://miro.medium.com/v2/resize:fit:786/format:webp/1*64N0_Nv61JtkHJu5b5T4Pw.png 786w, https://miro.medium.com/v2/resize:fit:828/format:webp/1*64N0_Nv61JtkHJu5b5T4Pw.png 828w, https://miro.medium.com/v2/resize:fit:1100/format:webp/1*64N0_Nv61JtkHJu5b5T4Pw.png 1100w, https://miro.medium.com/v2/resize:fit:1400/format:webp/1*64N0_Nv61JtkHJu5b5T4Pw.png 1400w" type="image/webp" sizes="(min-resolution: 4dppx) and (max-width: 700px) 50vw, (-webkit-min-device-pixel-ratio: 4) and (max-width: 700px) 50vw, (min-resolution: 3dppx) and (max-width: 700px) 67vw, (-webkit-min-device-pixel-ratio: 3) and (max-width: 700px) 65vw, (min-resolution: 2.5dppx) and (max-width: 700px) 80vw, (-webkit-min-device-pixel-ratio: 2.5) and (max-width: 700px) 80vw, (min-resolution: 2dppx) and (max-width: 700px) 100vw, (-webkit-min-device-pixel-ratio: 2) and (max-width: 700px) 100vw, 700px" /><source srcset="https://miro.medium.com/v2/resize:fit:640/1*64N0_Nv61JtkHJu5b5T4Pw.png 640w, https://miro.medium.com/v2/resize:fit:720/1*64N0_Nv61JtkHJu5b5T4Pw.png 720w, https://miro.medium.com/v2/resize:fit:750/1*64N0_Nv61JtkHJu5b5T4Pw.png 750w, https://miro.medium.com/v2/resize:fit:786/1*64N0_Nv61JtkHJu5b5T4Pw.png 786w, https://miro.medium.com/v2/resize:fit:828/1*64N0_Nv61JtkHJu5b5T4Pw.png 828w, https://miro.medium.com/v2/resize:fit:1100/1*64N0_Nv61JtkHJu5b5T4Pw.png 1100w, https://miro.medium.com/v2/resize:fit:1400/1*64N0_Nv61JtkHJu5b5T4Pw.png 1400w" sizes="(min-resolution: 4dppx) and (max-width: 700px) 50vw, (-webkit-min-device-pixel-ratio: 4) and (max-width: 700px) 50vw, (min-resolution: 3dppx) and (max-width: 700px) 67vw, (-webkit-min-device-pixel-ratio: 3) and (max-width: 700px) 65vw, (min-resolution: 2.5dppx) and (max-width: 700px) 80vw, (-webkit-min-device-pixel-ratio: 2.5) and (max-width: 700px) 80vw, (min-resolution: 2dppx) and (max-width: 700px) 100vw, (-webkit-min-device-pixel-ratio: 2) and (max-width: 700px) 100vw, 700px" data-testid="og" /><img data-recalc-dims="1" loading="lazy" decoding="async" class="bh lf nj c" role="presentation" src="https://i0.wp.com/miro.medium.com/v2/resize%3Afit%3A700/1%2A64N0_Nv61JtkHJu5b5T4Pw.png?resize=640%2C266&#038;ssl=1" alt="" width="640" height="266" /></picture></div>
</div>
</figure>
<p id="6336" class="pw-post-body-paragraph lx ly go lz b ma mb mc md me mf mg mh mi mj mk ml mm mn mo mp mq mr ms mt mu gh bk" data-selectable-paragraph="">The information found is the confirmation that the executable file is digitally signed by Connectwise, LLC.</p>
<p id="aa7b" class="pw-post-body-paragraph lx ly go lz b ma mb mc md me mf mg mh mi mj mk ml mm mn mo mp mq mr ms mt mu gh bk" data-selectable-paragraph="">To finalize our investigation, we checked the payload after execution</p>
<figure class="mz na nb nc nd ne mw mx paragraph-image">
<div class="nf ng fd nh bh ni" tabindex="0" role="button">
<div class="mw mx nu"><picture><source srcset="https://miro.medium.com/v2/resize:fit:640/format:webp/1*ci07p724mx8N-aekaRPmYQ.png 640w, https://miro.medium.com/v2/resize:fit:720/format:webp/1*ci07p724mx8N-aekaRPmYQ.png 720w, https://miro.medium.com/v2/resize:fit:750/format:webp/1*ci07p724mx8N-aekaRPmYQ.png 750w, https://miro.medium.com/v2/resize:fit:786/format:webp/1*ci07p724mx8N-aekaRPmYQ.png 786w, https://miro.medium.com/v2/resize:fit:828/format:webp/1*ci07p724mx8N-aekaRPmYQ.png 828w, https://miro.medium.com/v2/resize:fit:1100/format:webp/1*ci07p724mx8N-aekaRPmYQ.png 1100w, https://miro.medium.com/v2/resize:fit:1400/format:webp/1*ci07p724mx8N-aekaRPmYQ.png 1400w" type="image/webp" sizes="(min-resolution: 4dppx) and (max-width: 700px) 50vw, (-webkit-min-device-pixel-ratio: 4) and (max-width: 700px) 50vw, (min-resolution: 3dppx) and (max-width: 700px) 67vw, (-webkit-min-device-pixel-ratio: 3) and (max-width: 700px) 65vw, (min-resolution: 2.5dppx) and (max-width: 700px) 80vw, (-webkit-min-device-pixel-ratio: 2.5) and (max-width: 700px) 80vw, (min-resolution: 2dppx) and (max-width: 700px) 100vw, (-webkit-min-device-pixel-ratio: 2) and (max-width: 700px) 100vw, 700px" /><source srcset="https://miro.medium.com/v2/resize:fit:640/1*ci07p724mx8N-aekaRPmYQ.png 640w, https://miro.medium.com/v2/resize:fit:720/1*ci07p724mx8N-aekaRPmYQ.png 720w, https://miro.medium.com/v2/resize:fit:750/1*ci07p724mx8N-aekaRPmYQ.png 750w, https://miro.medium.com/v2/resize:fit:786/1*ci07p724mx8N-aekaRPmYQ.png 786w, https://miro.medium.com/v2/resize:fit:828/1*ci07p724mx8N-aekaRPmYQ.png 828w, https://miro.medium.com/v2/resize:fit:1100/1*ci07p724mx8N-aekaRPmYQ.png 1100w, https://miro.medium.com/v2/resize:fit:1400/1*ci07p724mx8N-aekaRPmYQ.png 1400w" sizes="(min-resolution: 4dppx) and (max-width: 700px) 50vw, (-webkit-min-device-pixel-ratio: 4) and (max-width: 700px) 50vw, (min-resolution: 3dppx) and (max-width: 700px) 67vw, (-webkit-min-device-pixel-ratio: 3) and (max-width: 700px) 65vw, (min-resolution: 2.5dppx) and (max-width: 700px) 80vw, (-webkit-min-device-pixel-ratio: 2.5) and (max-width: 700px) 80vw, (min-resolution: 2dppx) and (max-width: 700px) 100vw, (-webkit-min-device-pixel-ratio: 2) and (max-width: 700px) 100vw, 700px" data-testid="og" /><img data-recalc-dims="1" loading="lazy" decoding="async" class="bh lf nj c" role="presentation" src="https://i0.wp.com/miro.medium.com/v2/resize%3Afit%3A700/1%2Aci07p724mx8N-aekaRPmYQ.png?resize=640%2C366&#038;ssl=1" alt="" width="640" height="366" /></picture></div>
</div>
</figure>
<p id="5d51" class="pw-post-body-paragraph lx ly go lz b ma mb mc md me mf mg mh mi mj mk ml mm mn mo mp mq mr ms mt mu gh bk" data-selectable-paragraph="">If you are already familiar with malware analysis, you may notice some suspicious functions used such as :</p>
<p id="b403" class="pw-post-body-paragraph lx ly go lz b ma mb mc md me mf mg mh mi mj mk ml mm mn mo mp mq mr ms mt mu gh bk" data-selectable-paragraph="">LoadLibraryA</p>
<p id="1345" class="pw-post-body-paragraph lx ly go lz b ma mb mc md me mf mg mh mi mj mk ml mm mn mo mp mq mr ms mt mu gh bk" data-selectable-paragraph="">GetCurrentProcess</p>
<p id="173a" class="pw-post-body-paragraph lx ly go lz b ma mb mc md me mf mg mh mi mj mk ml mm mn mo mp mq mr ms mt mu gh bk" data-selectable-paragraph="">TerminateProcess</p>
<p id="fd56" class="pw-post-body-paragraph lx ly go lz b ma mb mc md me mf mg mh mi mj mk ml mm mn mo mp mq mr ms mt mu gh bk" data-selectable-paragraph="">CreateFileW</p>
<p id="8e72" class="pw-post-body-paragraph lx ly go lz b ma mb mc md me mf mg mh mi mj mk ml mm mn mo mp mq mr ms mt mu gh bk" data-selectable-paragraph="">GetProcAddress</p>
<p id="9055" class="pw-post-body-paragraph lx ly go lz b ma mb mc md me mf mg mh mi mj mk ml mm mn mo mp mq mr ms mt mu gh bk" data-selectable-paragraph="">HeapAlloc</p>
<p id="b9a8" class="pw-post-body-paragraph lx ly go lz b ma mb mc md me mf mg mh mi mj mk ml mm mn mo mp mq mr ms mt mu gh bk" data-selectable-paragraph="">WriteFile</p>
<p id="0105" class="pw-post-body-paragraph lx ly go lz b ma mb mc md me mf mg mh mi mj mk ml mm mn mo mp mq mr ms mt mu gh bk" data-selectable-paragraph="">ExitProcess</p>
<p id="7839" class="pw-post-body-paragraph lx ly go lz b ma mb mc md me mf mg mh mi mj mk ml mm mn mo mp mq mr ms mt mu gh bk" data-selectable-paragraph="">HeapReAllo</p>
<p id="dc43" class="pw-post-body-paragraph lx ly go lz b ma mb mc md me mf mg mh mi mj mk ml mm mn mo mp mq mr ms mt mu gh bk" data-selectable-paragraph="">The functions are usually used for code injection to hide the executable file from the EDR or Anti-Virus engine.</p>
<p id="5fd9" class="pw-post-body-paragraph lx ly go lz b ma mb mc md me mf mg mh mi mj mk ml mm mn mo mp mq mr ms mt mu gh bk" data-selectable-paragraph="">We can already limit here our investigation and come to the conclusion that the file is a malware and you should not run it.</p>
<p id="71a2" class="pw-post-body-paragraph lx ly go lz b ma mb mc md me mf mg mh mi mj mk ml mm mn mo mp mq mr ms mt mu gh bk" data-selectable-paragraph="">The usage of the digitally signed certificate from is out of scope (if you want to know ask them ahhh).</p>
<p id="cd81" class="pw-post-body-paragraph lx ly go lz b ma mb mc md me mf mg mh mi mj mk ml mm mn mo mp mq mr ms mt mu gh bk" data-selectable-paragraph="">We found many others malicious executable files using the signed certificate from the company: <a class="ag mv" href="https://bazaar.abuse.ch/browse.php?search=serial_number%3A0b9360051bccf66642998998d5ba97ce" target="_blank" rel="noopener ugc nofollow">MalwareBazaar | Browse malware samples</a>.</p>
<figure class="mz na nb nc nd ne mw mx paragraph-image">
<div class="nf ng fd nh bh ni" tabindex="0" role="button">
<div class="mw mx nv"><picture><source srcset="https://miro.medium.com/v2/resize:fit:640/format:webp/1*3GKbskYPN9V-lh3XwYOr0w.png 640w, https://miro.medium.com/v2/resize:fit:720/format:webp/1*3GKbskYPN9V-lh3XwYOr0w.png 720w, https://miro.medium.com/v2/resize:fit:750/format:webp/1*3GKbskYPN9V-lh3XwYOr0w.png 750w, https://miro.medium.com/v2/resize:fit:786/format:webp/1*3GKbskYPN9V-lh3XwYOr0w.png 786w, https://miro.medium.com/v2/resize:fit:828/format:webp/1*3GKbskYPN9V-lh3XwYOr0w.png 828w, https://miro.medium.com/v2/resize:fit:1100/format:webp/1*3GKbskYPN9V-lh3XwYOr0w.png 1100w, https://miro.medium.com/v2/resize:fit:1400/format:webp/1*3GKbskYPN9V-lh3XwYOr0w.png 1400w" type="image/webp" sizes="(min-resolution: 4dppx) and (max-width: 700px) 50vw, (-webkit-min-device-pixel-ratio: 4) and (max-width: 700px) 50vw, (min-resolution: 3dppx) and (max-width: 700px) 67vw, (-webkit-min-device-pixel-ratio: 3) and (max-width: 700px) 65vw, (min-resolution: 2.5dppx) and (max-width: 700px) 80vw, (-webkit-min-device-pixel-ratio: 2.5) and (max-width: 700px) 80vw, (min-resolution: 2dppx) and (max-width: 700px) 100vw, (-webkit-min-device-pixel-ratio: 2) and (max-width: 700px) 100vw, 700px" /><source srcset="https://miro.medium.com/v2/resize:fit:640/1*3GKbskYPN9V-lh3XwYOr0w.png 640w, https://miro.medium.com/v2/resize:fit:720/1*3GKbskYPN9V-lh3XwYOr0w.png 720w, https://miro.medium.com/v2/resize:fit:750/1*3GKbskYPN9V-lh3XwYOr0w.png 750w, https://miro.medium.com/v2/resize:fit:786/1*3GKbskYPN9V-lh3XwYOr0w.png 786w, https://miro.medium.com/v2/resize:fit:828/1*3GKbskYPN9V-lh3XwYOr0w.png 828w, https://miro.medium.com/v2/resize:fit:1100/1*3GKbskYPN9V-lh3XwYOr0w.png 1100w, https://miro.medium.com/v2/resize:fit:1400/1*3GKbskYPN9V-lh3XwYOr0w.png 1400w" sizes="(min-resolution: 4dppx) and (max-width: 700px) 50vw, (-webkit-min-device-pixel-ratio: 4) and (max-width: 700px) 50vw, (min-resolution: 3dppx) and (max-width: 700px) 67vw, (-webkit-min-device-pixel-ratio: 3) and (max-width: 700px) 65vw, (min-resolution: 2.5dppx) and (max-width: 700px) 80vw, (-webkit-min-device-pixel-ratio: 2.5) and (max-width: 700px) 80vw, (min-resolution: 2dppx) and (max-width: 700px) 100vw, (-webkit-min-device-pixel-ratio: 2) and (max-width: 700px) 100vw, 700px" data-testid="og" /><img data-recalc-dims="1" loading="lazy" decoding="async" class="bh lf nj c" role="presentation" src="https://i0.wp.com/miro.medium.com/v2/resize%3Afit%3A700/1%2A3GKbskYPN9V-lh3XwYOr0w.png?resize=640%2C405&#038;ssl=1" alt="" width="640" height="405" /></picture></div>
</div>
</figure>
<p id="5b70" class="pw-post-body-paragraph lx ly go lz b ma mb mc md me mf mg mh mi mj mk ml mm mn mo mp mq mr ms mt mu gh bk" data-selectable-paragraph="">Which means that you should always check any application signed by this organization.</p>
<p id="4c7c" class="pw-post-body-paragraph lx ly go lz b ma mb mc md me mf mg mh mi mj mk ml mm mn mo mp mq mr ms mt mu gh bk" data-selectable-paragraph="">If you already notice such activity within your organization, the following measure should be taken as fast as possible:</p>
<p id="5488" class="pw-post-body-paragraph lx ly go lz b ma mb mc md me mf mg mh mi mj mk ml mm mn mo mp mq mr ms mt mu gh bk" data-selectable-paragraph="">Change the user password.</p>
<p id="79a5" class="pw-post-body-paragraph lx ly go lz b ma mb mc md me mf mg mh mi mj mk ml mm mn mo mp mq mr ms mt mu gh bk" data-selectable-paragraph="">Re-image the host impacted.</p>
<p id="d888" class="pw-post-body-paragraph lx ly go lz b ma mb mc md me mf mg mh mi mj mk ml mm mn mo mp mq mr ms mt mu gh bk" data-selectable-paragraph="">Perform the full analyze on the host to detect any C2 or Persistency or privilege escalation method used.</p>
<p id="15ad" class="pw-post-body-paragraph lx ly go lz b ma mb mc md me mf mg mh mi mj mk ml mm mn mo mp mq mr ms mt mu gh bk" data-selectable-paragraph="">Block the URL or domain.</p>
<p id="81b9" class="pw-post-body-paragraph lx ly go lz b ma mb mc md me mf mg mh mi mj mk ml mm mn mo mp mq mr ms mt mu gh bk" data-selectable-paragraph="">Block the IOCs Hash.</p>
<div class="saboxplugin-wrap" itemtype="http://schema.org/Person" itemscope itemprop="author"><div class="saboxplugin-tab"><div class="saboxplugin-gravatar"><img loading="lazy" decoding="async" src="https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/05/cropped-osintafrica-1.jpg?fit=100%2C100&#038;ssl=1" srcset="https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/05/cropped-osintafrica-1.jpg?fit=200%2C200&#038;ssl=1 2x" width="100" height="100" alt="Bangaly Koita" class="avatar avatar-100 wp-user-avatar wp-user-avatar-100 photo avatar-default" /></div><div class="saboxplugin-authorname"><a href="https://www.osintafrica.net/author/admin/" class="vcard author" rel="author"><span class="fn">Bangaly Koita</span></a></div><div class="saboxplugin-desc"><div itemprop="description"><p>Bangaly Koita is a SOC Analyst and  Cyber Security researcher . As a passionate in cyber security,  he spends most of the time  writing articles and making videos online to share his knowledge and experience to the vast community of IT but in general Cyber Security. Feel free to contact me in case.</p>
</div></div><div class="saboxplugin-web "><a href="https://osintafrica.net" target="_self" >osintafrica.net</a></div><div class="clearfix"></div><div class="saboxplugin-socials "><a title="Linkedin" target="_blank" href="https://www.linkedin.com/in/bangaly-koita-68b8b912a/" rel="nofollow noopener" class="saboxplugin-icon-grey"><svg aria-hidden="true" class="sab-linkedin" role="img" xmlns="http://www.w3.org/2000/svg" viewbox="0 0 448 512"><path fill="currentColor" d="M100.3 480H7.4V180.9h92.9V480zM53.8 140.1C24.1 140.1 0 115.5 0 85.8 0 56.1 24.1 32 53.8 32c29.7 0 53.8 24.1 53.8 53.8 0 29.7-24.1 54.3-53.8 54.3zM448 480h-92.7V334.4c0-34.7-.7-79.2-48.3-79.2-48.3 0-55.7 37.7-55.7 76.7V480h-92.8V180.9h89.1v40.8h1.3c12.4-23.5 42.7-48.3 87.9-48.3 94 0 111.3 61.9 111.3 142.3V480z"></path></svg></span></a></div></div></div><p>The post <a href="https://www.osintafrica.net/malicious-connectwise-control-application-downloaded-in-the-wild/">Malicious ConnectWise Control application downloaded in the wild</a> first appeared on <a href="https://www.osintafrica.net">osintafrica</a>.</p>]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">877</post-id>	</item>
	</channel>
</rss>
